STAR Labs detailed a Linux kernel exploitation technique that uses prctl(PR_SET_VMA, PR_SET_VMA_ANON_NAME) to spray anon_vma_name objects into GFP_KERNEL-backed kmalloc caches. The method targets systems with CONFIG_ANON_VMA_NAME enabled and was tested on Linux kernel 6.1.37, with controllable allocations spanning kmalloc-8 through kmalloc-96. Researchers said the object is attractive for exploitation because it has only a 4-byte header, can be allocated and freed directly from user space, and supports dynamically sized data up to an 80-byte name plus terminator.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
STAR Labs published a write-up describing a Linux kernel exploitation technique that uses prctl(PR_SET_VMA, PR_SET_VMA_ANON_NAME) to spray dynamically sized anon_vma_name objects into GFP_KERNEL-backed kmalloc caches. The article explains allocation, reuse and freeing behavior, and notes the technique was tested on Linux kernel 6.1.37 with potential memory disclosure via /proc/<pid>/maps.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.